CVE-2022-36833
Status: ModifiedHigh (7.8)—
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.18%
- Percentile among all scored CVEs: 6
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-269
- CWE-269
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-36833",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 2.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "mobile.security@samsung.com",
"affectedData": [
{
"vendor": "Samsung Mobile",
"product": "Game Optimizing Service",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "3.3.04.0 in Android 10, 3.5.04.8 in Android 11 and above",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-08-05T16:15:15.030",
"references": [
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=08",
"tags": [
"Vendor Advisory"
],
"source": "mobile.security@samsung.com"
},
{
"url": "https://security.samsungmobile.com/serviceWeb.smsb?year=2022&month=08",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "mobile.security@samsung.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name."
},
{
"lang": "es",
"value": "Una vulnerabilidad de administración inapropiada de privilegios en Game Optimizing Service anterior a las versiones 3.3.04.0 en Android 10, y 3.5.04.8 en Android 11 y posteriores permite a un atacante local ejecutar una función oculta para el desarrollador cambiando el nombre del paquete"
}
],
"lastModified": "2026-06-17T04:54:01.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:gameoptimizingservice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "060B9683-14DC-43AF-A05B-8F97090B94B8",
"versionEndExcluding": "3.3.04.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D558D965-FA70-4822-A770-419E73BA9ED3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:samsung:gameoptimizingservice:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C93DB59-734D-4A2B-8AB2-56C3A1869942",
"versionEndExcluding": "3.5.04.8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "109DD7FD-3A48-4C3D-8E1A-4433B98E1E64"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "mobile.security@samsung.com"
}